Activity log for bug #431080

Date Who What changed Old value New value Message
2009-09-16 23:50:07 Scott Testerman bug added bug
2009-09-16 23:50:20 Scott Testerman visibility private public
2009-09-18 10:21:31 Scott Testerman description Binary package hint: drupal5 Drupal 5.20 has been released to fix a critical security vulnerability, as well as other, smaller issues. No new functionality has been included. Full details about the security issue addressed by this bugfix are available at http://drupal.org/node/579482 . The release announcement can be found at http://drupal.org/drupal-6.14 . Drupal 5.19 is not yet available upstream for merging. The vulnerability is: * Attacker can fix and reuse a victim's session ID. Binary package hint: drupal5 Drupal 5.20 has been released to fix a critical security vulnerability, as well as other, smaller issues. No new functionality has been included. Full details about the security issue addressed by this bugfix are available at http://drupal.org/node/579482 . The release announcement can be found at http://drupal.org/drupal-6.14 . Drupal 5.19 is not yet available upstream for merging. The vulnerability is: * Attacker can fix and reuse a victim's session ID. New upstream (non-Debian) source: ftp://ftp.osuosl.org/pub/drupal/files/projects/drupal-5.20.tar.gz
2009-09-18 10:22:27 Scott Testerman attachment added Drupal5-5.20 for Hardy http://launchpadlibrarian.net/32009990/drupal5_5.20-0ubuntu1.diff.gz
2009-09-18 10:23:18 Scott Testerman attachment added Drupal5-5.20 for Intrepid http://launchpadlibrarian.net/32010003/drupal5_5.20-0ubuntu1.diff.gz
2009-09-18 10:24:16 Scott Testerman attachment added Drupal5-5.20 for Jaunty http://launchpadlibrarian.net/32010040/drupal5_5.20-0ubuntu1.diff.gz
2009-09-18 10:25:00 Scott Testerman attachment added Drupal5-5.20 for Karmic http://launchpadlibrarian.net/32010059/drupal5_5.20-0ubuntu1.diff.gz
2009-09-18 21:22:03 Jamie Strandboge nominated for series Ubuntu Hardy
2009-09-18 21:22:03 Jamie Strandboge bug task added drupal5 (Ubuntu Hardy)
2009-09-18 21:22:03 Jamie Strandboge nominated for series Ubuntu Intrepid
2009-09-18 21:22:03 Jamie Strandboge bug task added drupal5 (Ubuntu Intrepid)
2009-09-18 21:22:03 Jamie Strandboge nominated for series Ubuntu Jaunty
2009-09-18 21:22:03 Jamie Strandboge bug task added drupal5 (Ubuntu Jaunty)
2009-09-18 21:22:03 Jamie Strandboge nominated for series Ubuntu Karmic
2009-09-18 21:22:03 Jamie Strandboge bug task added drupal5 (Ubuntu Karmic)
2009-09-18 21:22:30 Jamie Strandboge drupal5 (Ubuntu Hardy): status New Confirmed
2009-09-18 21:22:33 Jamie Strandboge drupal5 (Ubuntu Intrepid): status New Confirmed
2009-09-18 21:22:37 Jamie Strandboge drupal5 (Ubuntu Jaunty): status New Confirmed
2009-09-18 21:22:42 Jamie Strandboge drupal5 (Ubuntu Karmic): status New Confirmed
2009-09-19 07:57:03 Scott Testerman attachment added Drupal5-5.20 for Hardy debdiff http://launchpadlibrarian.net/32058293/drupal5_5.20-0ubuntu1.debdiff
2009-09-19 07:57:48 Scott Testerman attachment added Drupal5-5.20 for Intrepid debdiff http://launchpadlibrarian.net/32058309/drupal5_5.20-0ubuntu1.debdiff
2009-09-19 07:58:51 Scott Testerman attachment added Drupal5-5.20 for Jaunty debdiff http://launchpadlibrarian.net/32058336/drupal5_5.20-0ubuntu1.debdiff
2009-09-19 07:59:32 Scott Testerman attachment added Drupal5-5.20 for Karmic debdiff http://launchpadlibrarian.net/32058345/drupal5_5.20-0ubuntu1.debdiff
2009-09-19 12:36:45 Jamie Strandboge drupal5 (Ubuntu Hardy): status Confirmed In Progress
2009-09-19 12:36:47 Jamie Strandboge drupal5 (Ubuntu Intrepid): status Confirmed In Progress
2009-09-19 12:36:49 Jamie Strandboge drupal5 (Ubuntu Jaunty): status Confirmed In Progress
2009-09-19 12:36:51 Jamie Strandboge drupal5 (Ubuntu Karmic): status Confirmed In Progress
2009-09-19 12:57:00 Artur Rona bug watch added http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543940
2009-09-19 12:57:00 Artur Rona bug task added drupal5 (Debian)
2009-09-19 13:51:26 Bug Watch Updater drupal5 (Debian): status Unknown New
2009-09-20 02:01:03 Kees Cook drupal5 (Ubuntu Hardy): status In Progress Incomplete
2009-09-20 02:01:05 Kees Cook drupal5 (Ubuntu Intrepid): status In Progress Incomplete
2009-09-20 02:01:09 Kees Cook drupal5 (Ubuntu Karmic): status In Progress Incomplete
2009-09-20 02:01:15 Kees Cook drupal5 (Ubuntu Jaunty): status In Progress Incomplete
2009-10-06 16:08:35 Artur Rona drupal5 (Debian): importance Unknown Undecided
2009-10-06 16:08:35 Artur Rona drupal5 (Debian): remote watch Debian Bug tracker #543940
2009-10-06 16:09:22 Artur Rona drupal5 (Debian): status New Fix Released
2009-10-06 16:22:46 Artur Rona drupal5 (Ubuntu Karmic): assignee Artur Rona (ari-tczew)
2009-10-06 17:12:29 Artur Rona drupal5 (Ubuntu Karmic): status Incomplete In Progress
2009-10-07 01:59:21 Artur Rona drupal5 (Ubuntu Jaunty): status Incomplete In Progress
2009-10-07 01:59:21 Artur Rona drupal5 (Ubuntu Jaunty): assignee Artur Rona (ari-tczew)
2009-10-07 02:12:05 Artur Rona attachment removed Drupal5-5.20 for Hardy http://launchpadlibrarian.net/32009990/drupal5_5.20-0ubuntu1.diff.gz
2009-10-07 02:12:20 Artur Rona attachment removed Drupal5-5.20 for Intrepid http://launchpadlibrarian.net/32010003/drupal5_5.20-0ubuntu1.diff.gz
2009-10-07 02:12:45 Artur Rona attachment removed Drupal5-5.20 for Jaunty http://launchpadlibrarian.net/32010040/drupal5_5.20-0ubuntu1.diff.gz
2009-10-07 02:13:24 Artur Rona attachment removed Drupal5-5.20 for Karmic http://launchpadlibrarian.net/32010059/drupal5_5.20-0ubuntu1.diff.gz
2009-10-07 02:14:16 Artur Rona attachment removed Drupal5-5.20 for Hardy debdiff http://launchpadlibrarian.net/32058293/drupal5_5.20-0ubuntu1.debdiff
2009-10-07 02:14:20 Artur Rona attachment removed Drupal5-5.20 for Intrepid debdiff http://launchpadlibrarian.net/32058309/drupal5_5.20-0ubuntu1.debdiff
2009-10-07 02:14:24 Artur Rona attachment removed Drupal5-5.20 for Jaunty debdiff http://launchpadlibrarian.net/32058336/drupal5_5.20-0ubuntu1.debdiff
2009-10-07 02:14:26 Artur Rona attachment removed Drupal5-5.20 for Karmic debdiff http://launchpadlibrarian.net/32058345/drupal5_5.20-0ubuntu1.debdiff
2009-10-07 02:20:44 Artur Rona attachment added drupal5_5.18-1.1ubuntu2.debdiff http://launchpadlibrarian.net/33192633/drupal5_5.18-1.1ubuntu2.debdiff
2009-10-07 02:21:53 Artur Rona attachment removed drupal5_5.18-1.1ubuntu2.debdiff http://launchpadlibrarian.net/33192633/drupal5_5.18-1.1ubuntu2.debdiff
2009-10-07 02:23:12 Artur Rona attachment added drupal5_5.18-1.1ubuntu2.debdiff http://launchpadlibrarian.net/33192735/drupal5_5.18-1.1ubuntu2.debdiff
2009-10-07 02:37:07 Artur Rona bug task added drupal6 (Ubuntu)
2009-10-07 02:40:09 Artur Rona summary Drupal 5.20 released to fix critical security vulnerability Fix critical security vulnerability (SA-CORE-2009-008)
2009-10-07 02:40:35 Artur Rona drupal6 (Ubuntu Karmic): status New In Progress
2009-10-07 02:40:35 Artur Rona drupal6 (Ubuntu Karmic): assignee Artur Rona (ari-tczew)
2009-10-07 02:40:53 Artur Rona drupal6 (Ubuntu Jaunty): status New In Progress
2009-10-07 02:40:53 Artur Rona drupal6 (Ubuntu Jaunty): assignee Artur Rona (ari-tczew)
2009-10-07 02:42:07 Artur Rona description Binary package hint: drupal5 Drupal 5.20 has been released to fix a critical security vulnerability, as well as other, smaller issues. No new functionality has been included. Full details about the security issue addressed by this bugfix are available at http://drupal.org/node/579482 . The release announcement can be found at http://drupal.org/drupal-6.14 . Drupal 5.19 is not yet available upstream for merging. The vulnerability is: * Attacker can fix and reuse a victim's session ID. New upstream (non-Debian) source: ftp://ftp.osuosl.org/pub/drupal/files/projects/drupal-5.20.tar.gz Binary package hint: drupal5 Full details about the security issue addressed by this bugfix are available at http://drupal.org/node/579482 . The release announcement can be found at http://drupal.org/drupal-6.14 . The vulnerability is: * Attacker can fix and reuse a victim's session ID.
2009-10-07 02:49:39 Artur Rona tags patch
2009-10-07 15:35:30 Artur Rona attachment removed drupal5_5.18-1.1ubuntu2.debdiff http://launchpadlibrarian.net/33192735/drupal5_5.18-1.1ubuntu2.debdiff
2009-10-07 15:37:36 Artur Rona attachment added drupal5_5.18-1.1ubuntu2.debdiff http://launchpadlibrarian.net/33234876/drupal5_5.18-1.1ubuntu2.debdiff
2009-10-07 15:41:13 Artur Rona drupal5 (Ubuntu Karmic): status In Progress New
2009-10-07 15:41:13 Artur Rona drupal5 (Ubuntu Karmic): assignee Artur Rona (ari-tczew)
2009-10-08 20:30:50 Kees Cook drupal5 (Ubuntu Jaunty): status In Progress Triaged
2009-10-08 20:32:25 Kees Cook drupal6 (Ubuntu Jaunty): status In Progress Triaged
2009-10-09 16:25:23 Launchpad Janitor branch linked lp:ubuntu/drupal5
2009-10-09 16:25:21 Launchpad Janitor drupal5 (Ubuntu Karmic): status New Fix Released
2009-10-10 00:57:20 StefanPotyra removed subscriber MOTU Release Team
2009-10-10 16:26:40 Artur Rona bug watch added http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547140
2009-10-10 16:26:40 Artur Rona bug task added drupal6 (Debian)
2009-10-10 16:41:27 Bug Watch Updater drupal6 (Debian): status Unknown Fix Released
2009-10-10 16:49:15 Artur Rona attachment added drupal6_6.12-1.1ubuntu1.debdiff http://launchpadlibrarian.net/33413195/drupal6_6.12-1.1ubuntu1.debdiff
2009-10-10 17:06:40 Artur Rona cve linked 2009-2372
2009-10-10 17:07:55 Artur Rona cve linked 2009-2374
2009-10-10 17:10:29 Artur Rona cve unlinked 2009-2372
2009-10-10 17:16:09 Artur Rona drupal6 (Ubuntu Hardy): status New Invalid
2009-10-10 17:16:34 Artur Rona drupal6 (Ubuntu Intrepid): status New Invalid
2009-10-10 17:18:11 Artur Rona drupal6 (Ubuntu Karmic): status In Progress New
2009-10-10 17:18:11 Artur Rona drupal6 (Ubuntu Karmic): assignee Artur Rona (ari-tczew)
2009-10-13 13:36:57 Artur Rona drupal5 (Debian): importance Undecided Unknown
2009-10-13 13:36:57 Artur Rona drupal5 (Debian): status Fix Released Unknown
2009-10-13 13:36:57 Artur Rona drupal5 (Debian): remote watch Debian Bug tracker #543940
2009-10-13 22:34:48 Bug Watch Updater drupal5 (Debian): status Unknown Fix Released
2009-10-16 12:51:50 Michael Terry drupal6 (Ubuntu Karmic): status New Fix Committed
2009-10-16 14:02:27 Launchpad Janitor drupal6 (Ubuntu Karmic): status Fix Committed Fix Released
2009-10-16 20:30:49 Artur Rona branch linked lp:ubuntu/drupal6
2009-10-20 12:50:54 Artur Rona drupal5 (Ubuntu Jaunty): status Triaged In Progress
2009-10-24 01:12:28 Artur Rona attachment added drupal5_5.15-1ubuntu1.1.debdiff http://launchpadlibrarian.net/34301159/drupal5_5.15-1ubuntu1.1.debdiff
2009-10-24 01:15:05 Artur Rona drupal5 (Ubuntu Jaunty): status In Progress New
2009-10-24 01:15:05 Artur Rona drupal5 (Ubuntu Jaunty): assignee Artur Rona (ari-tczew)
2009-10-24 19:09:35 Artur Rona drupal5 (Ubuntu Jaunty): status New In Progress
2009-10-24 19:09:35 Artur Rona drupal5 (Ubuntu Jaunty): assignee Artur Rona (ari-tczew)
2009-10-24 19:10:19 Artur Rona attachment removed drupal5_5.15-1ubuntu1.1.debdiff http://launchpadlibrarian.net/34301159/drupal5_5.15-1ubuntu1.1.debdiff
2009-10-24 21:37:56 Artur Rona attachment added drupal5_5.15-1ubuntu1.1.debdiff http://launchpadlibrarian.net/34335941/drupal5_5.15-1ubuntu1.1.debdiff
2009-10-24 21:59:58 Artur Rona branch linked lp:ubuntu/jaunty/drupal5
2009-10-24 22:00:27 Artur Rona drupal5 (Ubuntu Jaunty): status In Progress New
2009-10-24 22:00:27 Artur Rona drupal5 (Ubuntu Jaunty): assignee Artur Rona (ari-tczew)
2009-10-25 02:11:38 Scott Kitterman removed subscriber MOTU Release Team
2009-10-25 12:56:23 Artur Rona drupal6 (Ubuntu Jaunty): status Triaged In Progress
2009-10-25 13:36:06 Artur Rona attachment added drupal6_6.10-1ubuntu0.1.debdiff http://launchpadlibrarian.net/34357528/drupal6_6.10-1ubuntu0.1.debdiff
2009-10-25 13:37:57 Artur Rona drupal6 (Ubuntu Jaunty): status In Progress New
2009-10-25 13:37:57 Artur Rona drupal6 (Ubuntu Jaunty): assignee Artur Rona (ari-tczew)
2009-10-25 15:22:08 Artur Rona attachment removed drupal6_6.10-1ubuntu0.1.debdiff http://launchpadlibrarian.net/34357528/drupal6_6.10-1ubuntu0.1.debdiff
2009-10-25 15:25:02 Artur Rona attachment added drupal6_6.10-1ubuntu0.1.debdiff http://launchpadlibrarian.net/34360597/drupal6_6.10-1ubuntu0.1.debdiff
2009-10-25 17:31:57 Artur Rona cve linked 2009-2373
2009-10-25 17:32:21 Artur Rona cve linked 2009-2372
2009-10-25 17:32:50 Artur Rona cve linked 2009-1576
2009-10-26 13:03:32 Launchpad Janitor drupal6 (Ubuntu Jaunty): status New Fix Released
2009-10-26 13:03:32 Launchpad Janitor drupal5 (Ubuntu Jaunty): status New Fix Released
2009-10-26 17:30:59 Artur Rona drupal5 (Ubuntu Hardy): assignee Artur Rona (ari-tczew)
2009-10-26 17:31:33 Artur Rona drupal5 (Ubuntu Intrepid): assignee Artur Rona (ari-tczew)
2009-10-28 18:35:29 Artur Rona branch linked lp:ubuntu/jaunty/drupal6
2009-10-31 17:14:13 Artur Rona cve linked 2008-6171
2009-10-31 17:19:36 Artur Rona cve linked 2008-6533
2009-10-31 17:19:58 Artur Rona cve linked 2008-6532
2009-10-31 17:20:57 Artur Rona summary Fix critical security vulnerability (SA-CORE-2009-008) Fix critical security issues in drupal packages
2009-11-01 11:38:58 Steve Langasek removed subscriber Ubuntu Release Team
2009-11-03 14:54:18 Launchpad Janitor branch linked lp:~ubuntu-branches/ubuntu/jaunty/drupal5/jaunty-security
2009-11-06 05:54:28 Launchpad Janitor branch linked lp:ubuntu/jaunty-updates/drupal6
2009-12-13 21:01:30 Artur Rona drupal5 (Ubuntu Intrepid): status Incomplete In Progress
2009-12-15 15:35:00 Artur Rona attachment added drupal5_5.10-1ubuntu1.1.debdiff http://launchpadlibrarian.net/36822460/drupal5_5.10-1ubuntu1.1.debdiff
2009-12-15 15:35:32 Artur Rona drupal5 (Ubuntu Intrepid): status In Progress New
2009-12-15 15:35:32 Artur Rona drupal5 (Ubuntu Intrepid): assignee Artur Rona (ari-tczew)
2009-12-21 19:30:48 Artur Rona attachment removed drupal5_5.10-1ubuntu1.1.debdiff http://launchpadlibrarian.net/36822460/drupal5_5.10-1ubuntu1.1.debdiff
2009-12-21 19:31:09 Artur Rona drupal5 (Ubuntu Intrepid): status New In Progress
2009-12-21 19:31:09 Artur Rona drupal5 (Ubuntu Intrepid): assignee Artur Rona (ari-tczew)
2009-12-21 19:31:25 Artur Rona drupal5 (Ubuntu Hardy): status Incomplete In Progress
2009-12-21 23:45:00 Artur Rona attachment removed drupal5_5.15-1ubuntu1.1.debdiff http://launchpadlibrarian.net/34335941/drupal5_5.15-1ubuntu1.1.debdiff
2009-12-21 23:45:20 Artur Rona attachment removed drupal6_6.10-1ubuntu0.1.debdiff http://launchpadlibrarian.net/34360597/drupal6_6.10-1ubuntu0.1.debdiff
2009-12-21 23:46:12 Artur Rona attachment removed drupal5_5.18-1.1ubuntu2.debdiff http://launchpadlibrarian.net/33234876/drupal5_5.18-1.1ubuntu2.debdiff
2009-12-21 23:46:26 Artur Rona attachment removed drupal6_6.12-1.1ubuntu1.debdiff http://launchpadlibrarian.net/33413195/drupal6_6.12-1.1ubuntu1.debdiff
2009-12-22 00:02:12 Benjamin Drung removed subscriber Ubuntu Sponsors for universe
2009-12-22 12:57:59 Artur Rona attachment added drupal5_5.10-1ubuntu1.1.debdiff http://launchpadlibrarian.net/37086578/drupal5_5.10-1ubuntu1.1.debdiff
2009-12-22 12:58:23 Artur Rona drupal5 (Ubuntu Intrepid): status In Progress New
2009-12-22 13:01:44 Artur Rona drupal5 (Ubuntu Intrepid): assignee Artur Rona (ari-tczew)
2010-01-03 15:15:32 Artur Rona drupal5 (Ubuntu Intrepid): status New Confirmed
2010-01-03 19:11:44 Kees Cook drupal5 (Ubuntu Intrepid): status Confirmed Fix Committed
2010-01-03 19:12:30 Kees Cook removed subscriber Ubuntu Security Sponsors Team
2010-01-03 20:03:34 Launchpad Janitor drupal5 (Ubuntu Intrepid): status Fix Committed Fix Released
2010-01-07 13:20:46 Launchpad Janitor branch linked lp:ubuntu/intrepid-security/drupal5
2010-01-15 19:56:09 Marc Deslauriers removed subscriber Ubuntu Security Sponsors Team
2010-01-31 15:04:01 Artur Rona attachment removed drupal5_5.10-1ubuntu1.1.debdiff http://launchpadlibrarian.net/37086578/drupal5_5.10-1ubuntu1.1.debdiff
2010-01-31 15:04:29 Artur Rona attachment added drupal5_5.7-1ubuntu1.2.debdiff http://launchpadlibrarian.net/38581079/drupal5_5.7-1ubuntu1.2.debdiff
2010-01-31 15:05:23 Artur Rona drupal5 (Ubuntu Hardy): status In Progress Confirmed
2010-01-31 15:05:23 Artur Rona drupal5 (Ubuntu Hardy): assignee Artur Rona (ari-tczew)
2010-01-31 22:59:17 Martin Pitt removed subscriber MOTU Stable Release Updates
2010-02-08 16:05:50 Marc Deslauriers drupal5 (Ubuntu Hardy): status Confirmed Fix Committed
2010-02-08 19:03:22 Launchpad Janitor drupal5 (Ubuntu Hardy): status Fix Committed Fix Released
2010-02-08 19:03:22 Launchpad Janitor cve linked 2009-4370
2010-02-08 19:10:25 Launchpad Janitor branch linked lp:ubuntu/hardy-security/drupal5